AI agents are starting to execute contracts, payments and trades on their own, and the market is running into a basic problem: there is still no shared way to verify who an agent actually is. That gap has put KYA, short for Know Your Agent, at the center of a new standards race. Visa, the Ethereum-based ERC-8004 effort, Trulioo and Sumsub are all building different identity and verification frameworks for this layer.
KYA becomes critical once agents leave closed platforms
The source makes a clear distinction between internal and external environments. Inside centralized platforms such as Google, OpenAI and Coinbase, existing user KYC and platform accountability can be enough. KYA matters most when independently deployed autonomous agents move outside those systems and interact with DEXs, agent-to-agent payments and merchant checkouts.
That is where the accountability problem gets harder. An AI agent can place orders, move funds and act on instructions without direct human intervention at the moment of execution, yet there is no universal standard to prove its origin, authority or responsibility. In A2A settings, that creates room for unauthorized transactions, fraud and unclear liability. The source frames KYA as the trust layer designed to close that gap.
ERC-8004 proposes an onchain identity stack for agents
On the blockchain side, ERC-8004 is presented as an NFT-based identity standard for agents. It adds an identity layer on top of ERC-721, mints one NFT as a unique ID for each agent, and pairs that with three onchain registries: Identity, Reputation and Validation.
The point of that structure is to turn identity, reputation and verification records into composable onchain modules. The source compares its potential role with earlier Ethereum standards. ERC-20 standardized token issuance, ERC-721 helped create the NFT market, and ERC-8004 is being positioned as a similar base layer for the agent era. If autonomous agents connect more deeply with onchain finance and applications, standards of this kind could carry more weight.
Visa ties agent verification directly to payment rails
Visa is taking a payment-first route. According to the source, Visa TAP issues identity credentials to agents in the form of Agent Intent, functioning like an identity card for transactions. No key, no transaction. Those keys are only released after Visa pre-approval. For each payment, the merchant receives not one signature but three: Visa approval, the principal and the payment method.
This setup shows Visa trying to embed verification into its existing network logic before agent-driven commerce scales up. The source says Visa is packaging KYA together with payments through Visa Intelligent Commerce. If agent payments keep using card rails and that package becomes a default option, Visa could preserve its position even as the payment flow changes.
Trulioo and Sumsub extend existing compliance infrastructure
Another track is being shaped by companies already active in KYC and KYB. Trulioo’s model extends that verification stack into KYA. The source compares it with the SSL certificate model: a DPA acts in a role similar to an SSL CA, verifies the developer through KYB and the user through KYC, then issues a DAP to the agent.
DAP is described as a digital passport for an agent. It is not a static one-time credential. It refreshes and is revalidated with each transaction. If delegation is revoked or an anomaly is detected, the DAP can be invalidated immediately. That makes KYA a continuous trust check rather than a one-off onboarding step.
Sumsub is focusing on what happens after issuance. The source says its system re-verifies the human identity currently in use when an agent attempts an abnormal transaction. Built on compliance verification systems the company has operated since 2015, this approach places more emphasis on live anomaly detection than on simple front-end approval.
Regulators are already moving at the national level
The standards fight is not limited to private companies. The source notes that the EU AI Act requires operator identity to be included in activity logs for high-risk AI systems. In the United States, NIST has listed agent identity management as a priority standards area. Singapore has also released what the source calls the world’s first national governance framework for agentic AI.
The article draws a parallel with the industry split that followed the FATF Travel Rule in 2019, when the cost of KYC and AML infrastructure became a dividing line for VASPs. By the same logic, KYA infrastructure may become a gatekeeping requirement for the next wave of AI-agent participation. The source does not expect a single winner. Instead, it argues the market is likely to break into segments, with leadership determined by how identity standards connect to merchants, payment networks and existing KYC client bases.

